CVE-2023-28647

MEDIUM

Nextcloud iOS <4.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app and bypass the Nextcloud pin/password protection and gain access to a users files. It is recommended that the Nextcloud iOS app is upgraded to 4.7.0. There are no known workarounds for this vulnerability.

Scores

CVSS v3 4.4
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-281
Status published
Products (1)
nextcloud/nextcloud < 4.7.0
Published Mar 30, 2023
Tracked Since Feb 18, 2026